North Korean hackers were responsible for nearly half of the documented state-backed cyber intrusions against the US technology sector over the past year, according to a new report from cybersecurity company CrowdStrike.
The report, which covers the period from April 2025 to May 2026, found that the group CrowdStrike tracks as “Famous Chollima” accounted for 47 per cent of all state-backed activity aimed at the tech industry.
Hackers posed as remote workers
CrowdStrike said North Korean operatives increasingly impersonated software developers, coders and IT professionals to secure remote jobs at technology companies in the United States, Europe and Asia.
According to the report, the attackers used:
- AI-generated deepfake images
- Stolen passports
- Fraudulent driver’s licences
- Fake identities posing as Americans and other foreign nationals
The tactics enabled them to gain employment under false identities.
Focus on hands-on-keyboard attacks
The company said the findings are based on so-called “hands-on-keyboard” intrusions, which involve direct human activity rather than automated malware.
These attacks typically begin with stolen passwords or credentials and involve the misuse of legitimate tools already present in a company’s systems.
Such methods allow attackers to maintain long-term access while avoiding detection by conventional security software.
Salaries and stolen data
Once employed, the operatives earned salaries that were allegedly channelled back to the North Korean government, according to CrowdStrike.
The report said they also stole:
- Intellectual property
- Sensitive corporate information
When discovered, some attackers threatened to release the stolen data unless companies paid a ransom.
Cryptocurrency remains a target
North Korean hackers also continued to target blockchain developers and cryptocurrency firms.
CrowdStrike said the objective was to steal digital assets that could help the regime bypass restrictions imposed by Western countries and the United Nations over its nuclear weapons programme.
According to the report, North Korea has stolen billions of dollars in cryptocurrency over the years, including around $2 billion in 2025 alone.
Funding concerns
CrowdStrike said the cyber operations are aimed at generating funds for Pyongyang’s nuclear weapons programme, which is prohibited under international law.
The report highlights the growing role of North Korean-linked groups in cyber espionage and financially motivated attacks targeting the global technology industry.
TL;DR:
North Korean hackers accounted for 47% of state-backed cyber activity targeting the US tech sector between April 2025 and May 2026, according to CrowdStrike. The operatives allegedly posed as remote IT workers, stole sensitive data and targeted cryptocurrency assets.
AI summary:
- CrowdStrike attributed 47% of state-backed attacks on the US tech sector to North Korea.
- The group known as “Famous Chollima” posed as remote IT workers.
- Attackers used deepfakes and forged identity documents.
- They allegedly stole corporate data and demanded ransom payments.
- North Korea is estimated to have stolen about $2 billion in cryptocurrency during 2025.








